Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,036
Critical923
High3,047
Medium10,866
Reset
Showing 5901-5920 of 15036 records
Threat Entry Updated 2025-02-25

CVE-2024-13789 - Ravpage Plugin

The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted input from the 'paramsv2' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may…

PLUGIN Ravpage

CVE-2024-13789

CRITICAL CVSS 9.8 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13753 - Ultimate Classified Listings Plugin

The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers to modify victim's email via a forged request, which might lead to account takeover, granted they can trick a user into performing an action such as clicking on a link.

PLUGIN Ultimate Classified Listings

CVE-2024-13753

HIGH CVSS 8.1 2025-02-20
Threat Entry Updated 2025-09-10

CVE-2024-13792 - Woocommerce Food Plugin

The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Woocommerce Food

CVE-2024-13792

HIGH CVSS 7.3 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13520 - Gift Vouchers Plugin

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.6. This makes it possible for unauthenticated attackers to update the value, expiration date, and user note for any gift voucher.

PLUGIN Gift Vouchers

CVE-2024-13520

MEDIUM CVSS 5.3 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13748 - Ultimate Classified Listings Plugin

The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Ultimate Classified Listings

CVE-2024-13748

MEDIUM CVSS 4.4 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13476 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_dropship' AJAX endpoint in all versions up to, and including, 2.3.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13476

HIGH CVSS 7.5 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13888 - Wpmobile App Plugin

The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

PLUGIN Wpmobile App

CVE-2024-13888

HIGH CVSS 7.2 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2025-1064 - Login Signup Popup Plugin

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all versions up to, and including, 2.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Login Signup Popup

CVE-2025-1064

MEDIUM CVSS 6.4 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2025-0897 - Modal Window Plugin

The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 6.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Modal Window

CVE-2025-0897

MEDIUM CVSS 6.4 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13155 - Unlimited Elements For Elementor Plugin

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: Since the widget code isn't part of the code base, to apply the patch, the affected widget: Transparent Split…

PLUGIN Unlimited Elements For Elementor

CVE-2024-13155

MEDIUM CVSS 6.4 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13445 - Website Builder Plugin

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Website Builder

CVE-2024-13445

MEDIUM CVSS 6.4 2025-02-20
Threat Entry Updated 2025-02-25

CVE-2024-13534 - Small Package Quotes Plugin

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Small Package Quotes

CVE-2024-13534

HIGH CVSS 7.5 2025-02-19
Threat Entry Updated 2025-02-25

CVE-2024-13533 - Small Package Quotes Plugin

The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Small Package Quotes

CVE-2024-13533

HIGH CVSS 7.5 2025-02-19
Threat Entry Updated 2025-02-25

CVE-2024-13491 - Small Package Quotes Plugin

The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Small Package Quotes

CVE-2024-13491

HIGH CVSS 7.5 2025-02-19
Threat Entry Updated 2025-02-25

CVE-2024-13485 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13485

HIGH CVSS 7.5 2025-02-19
Threat Entry Updated 2025-02-25

CVE-2025-0916 - Yaysmtp Plugin

The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: The vulnerability has been initially patched in version 2.4.8 and was reintroduced in version 2.4.9 with the removal of the wp_kses_post() built-in WordPress sanitization function.

PLUGIN Yaysmtp

CVE-2025-0916

HIGH CVSS 7.2 2025-02-19
Threat Entry Updated 2025-02-25

CVE-2025-0968 - Elementskit Elementor Addons Plugin

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, trashed and private items.

PLUGIN Elementskit Elementor Addons

CVE-2025-0968

MEDIUM CVSS 5.3 2025-02-19
Threat Entry Updated 2025-02-25

CVE-2024-13483 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13483

HIGH CVSS 7.5 2025-02-19
Threat Entry Updated 2025-03-11

CVE-2024-13481 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13481

HIGH CVSS 7.5 2025-02-19
Threat Entry Updated 2025-02-25

CVE-2024-13479 - Ltl Freight Quotes Plugin

The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Ltl Freight Quotes

CVE-2024-13479

HIGH CVSS 7.5 2025-02-19
Scroll to top